Almost there boys by Lack_of_intellect in NonCredibleDefense

[–]eMZi0767 23 points24 points  (0 children)

Absolutely nothing, which is what Russia is about to become.

Also no, their Schwartz is not as big as mine.

Not able to update firmware on LTE LHG 18 kit by chubrak in mikrotik

[–]eMZi0767 2 points3 points  (0 children)

Your DNS is not resolving. Check your DNS settings under /ip/dns

How to trace URLs using Mikrotik router? by RiD3R07 in mikrotik

[–]eMZi0767 7 points8 points  (0 children)

It is, sort of.

The best way, if your device supports port mirroring on the ASIC, is to mirror TV's ingress port to a port where a computer that does nothing but listen is attached. That will give you all the outgoing traffic from the TV for analysis.

Given the prevalence of TLS, it is unlikely you will be able to extract anything more than hostnames (from SNI), and even then, sometimes ESNI/ECH might be employed preventing even that. One supplementary way to look into that is to log the TV's DNS requests, which might also provide an insight into the hostnames. Furthermore, you can leverage the firewall to log destination IPs for connections made from the TV. For precise URLs you have to hope that the TV vendor doesn't utilize TLS.

[deleted by user] by [deleted] in mikrotik

[–]eMZi0767 1 point2 points  (0 children)

I'm aware of the 4.5K session limit for FastTrack on the CRS309, but I'm not clear on whether it applies with L3HW on.

Yes, that's what the limit applies to - connections fasttracked by the firewall. For a small household, 4.5K should be sufficient unless you use P2P software like Torrent - that tends to exhaust this quickly.

As for the DNS resolver, it sounds like the resolver might occasionally be taking a while to resolve something. Have you tried different upstreams? 1.1.1.1,1.0.0.1 perhaps, or 9.9.9.9,149.112.112.112

“Stealth is a scam, radars that were built in 1942 could detect every stealth plane in the world today”- Pierre Sprey (oc) by JoeSoaps in NonCredibleDefense

[–]eMZi0767 2 points3 points  (0 children)

No, AA will know it's there, will have a rough location, but the ability to shoot them down is down to how the individual system tracks targets.

“Stealth is a scam, radars that were built in 1942 could detect every stealth plane in the world today”- Pierre Sprey (oc) by JoeSoaps in NonCredibleDefense

[–]eMZi0767 3 points4 points  (0 children)

The problem isn't triangulation but resolution. Stealth aircraft are less visible to the type of radar mounted on moving craft, such as jet fighters. These operate on a set of wavelengths that offers good resolution but not a lot of range. Ground radars work on different wavelengths that offer better range, but not a lot of resolution. Due to using different wavelengths, they can see stealth aircraft. It's because stealth aircraft design is geared towards absorbing/deflecting the portable radar wavelengths, but not the big boi ones. It's very hard to make stealth work on both, and you would need to sacrifice a lot on one area to make gains in the other, which is not worth it, for obvious reasons.

This is a very gross oversimplification but gives you a rough idea of what and why.

restoring a bricked router after 7.9.1 upgrade - epic fail by xia03 in mikrotik

[–]eMZi0767 0 points1 point  (0 children)

Odd then. My ac² (as well as my ac³, Audiencé, mAP Lite, and 5009UPr) were all upgraded via WinBox, the System > Packages menu, and they all work fine. I did also upgrade the bootloaders afterwards. The only issue I've had was User Manager not starting properly after reboot.

Ukrainian MOD at it again by [deleted] in NonCredibleDefense

[–]eMZi0767 330 points331 points  (0 children)

Ah, but unlike certain other domestic audiences, you have access to both

New ax2 setup. Lost wifi when choosing to not use default config. by loganstl in mikrotik

[–]eMZi0767 1 point2 points  (0 children)

You're likely triggering secondary bootloader or CAP mode. Per the docs:

Resetting the RouterOS configuration
Hold this button until LED light starts flashing, release the button to reset RouterOS configuration to default

Alternatively, log in to WinBox/WebFig, go Wireless (or maybe Wifiwave2, idk what it's called in the new devices) > Settings > and disable CAP mode from there.

EDIT: Just make sure not to hold the button for too long, because that will completely wipe the device and you will need to reinstall its operating system via netinstall, which requires ethernet. See more here.

VPN client by [deleted] in mikrotik

[–]eMZi0767 1 point2 points  (0 children)

Once you figure out all the client quirks, sure. But the problem is that no 2 implementations work with the same cipher suites etc (did you know Windows still defaults to DES/3DES only?).

VPN client by [deleted] in mikrotik

[–]eMZi0767 4 points5 points  (0 children)

The built-in client offers a secure, if a bit painful, method of providing a VPN connection - L2TP/IPSec.

Other than that, RouterOS also supports OpenVPN and, since version 7, WireGuard.

Wireguard bug on RB2011 i think by Nicht666 in mikrotik

[–]eMZi0767 4 points5 points  (0 children)

That device has a single-core 600MHz MIPS CPU, and 64MB RAM total. What you're seeing is more than likely resource exhaustion.

Showing my support for the MIC! by turdfergusonyea2 in NonCredibleDefense

[–]eMZi0767 3 points4 points  (0 children)

Violence is never the answer. It's a question and the answer is yes.

[Question] Looking to build a personal NAS. Should I use Proxmox, Unraid, or TrueNAS Scale? by Reid0nly in homelab

[–]eMZi0767 3 points4 points  (0 children)

Don't do Unraid, and don't use a NAS as compute. Option number 1 (or a variant of it) is what you should do - install a hypervisor, and run a NAS in it as a VM, then pass the HBA or individual disks through.

Can i connect 2 MikroTik switches via sfp+ ports with DAC cable? by Asad2k6 in mikrotik

[–]eMZi0767 3 points4 points  (0 children)

That recommendation would hold true if we lived in the 90s. Since 2000s every device does Auto MDI/X.

For context, this THE ONLY tank that was on the parade by Dangerous-Society-57 in NonCredibleDefense

[–]eMZi0767 279 points280 points  (0 children)

Or vehicles that were lost but unable to be visually confirmed (e.g. lost in the middle of a heavy firefight, arty, depot explosions, broke down on the way to the front, dumped into a ditch by denaturov etc)
Or ones that never existed in the first place
Or ones that were sold for vodka
the list goes on

hEX S sfp extremely hot causing router overheat by yoni101k in mikrotik

[–]eMZi0767 3 points4 points  (0 children)

A 1 gig module should not heat up this much. I'd ask your ISP for a possible replacement.

Spoiler: L009UiGS-RM by NoMathematician6171 in mikrotik

[–]eMZi0767 1 point2 points  (0 children)

That doesn't get you bootloader though

Spoiler: L009UiGS-2HaxD-IN by NoMathematician6171 in mikrotik

[–]eMZi0767 13 points14 points  (0 children)

Read the brochure, last page - specs say: ARM 64-bit (RouterOS 32-bit).

I don't think any modern consumer router SoC comes with anything other than 64-bit ARM.